Evanston Township High School District 202

Ransomware disrupted Evanston Township High School District 202 systems, phones, internet and safety functions beginning June 7, forcing a two-day campus closure and cancellations. The district documented limited systems and phased recovery through July 17, and the school opened for the 2026-27 year on August 17 without a newer report of a specific continuing operational disruption. Material impacts are presumed resolved, while payment, personal-information access and actor attribution remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.
A primary service, system, platform, or operational capability became entirely unavailable.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
A specific application or software platform became unavailable or unusable.
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
DysruptionHub assesses with high confidence that Evanston Township High School District 202 experienced a ransomware attack beginning June 7, 2026. The district’s incident page confirms that the event disrupted district systems, internet services and computer infrastructure. Our initial report and CBS News Chicago documented the immediate campus, communications and safety effects.
The district has not identified the access vector, ransomware family, compromised accounts, encryption scope or responsible actor. Ransomware is confirmed by the victim, but the technical and attribution picture remains limited.
The attack disrupted network connectivity, internet, phones, staff email and Google accounts, eSchool, Home Access Center, myETHS, door access, public-address functions and other emergency or operational systems. Because systems required for safe operations were unavailable, the school closed campus June 8-9 and canceled summer school, sports camps and other activities. Campus reopened June 10, but that did not mark full technology restoration.
In a July 16 school-year preparation statement, Superintendent Marcus Campbell said core servers had been inaccessible for about a month and that teams were rebuilding critical systems and restoring services. The district expected some tools, processes and timelines to function differently, with services returning in phases and temporary workarounds continuing into the school year.
The district’s incident page documented limited system access, unavailable district phones and legacy student-information portals, device-review requirements and no specific timeline for full restoration. That page says it was last updated July 17, which is the latest date on which the public record specifically establishes continuing operational impact.
The district began rolling out Infinite Campus on August 12 as a replacement for myETHS and Home Access Center. The Evanston RoundTable described a gradual introduction of access and features, but it did not identify an incident-caused service outage or material operational limitation continuing on that date.
Students returned for the first day of the 2026-27 school year on August 17. Campbell told the Evanston RoundTable that opening required an extraordinary collective effort and that the district would be dealing with ripple effects for some time. The report did not identify a specific outage, degraded service or emergency workaround still occurring that day.
More than 30 days passed after the July 17 operational-impact observation without newer evidence of a concrete continuing disruption. The incident is therefore presumed resolved. It is not classified as resolved because the district has not issued a definitive restoration notice or comprehensive all-clear.
CBS reported on June 8 that the district had not yet received a money demand. Later Evanston RoundTable reporting said attackers requested a ransom and that district officials had not disclosed whether it was paid. Campbell declined to comment on payment on August 17. This supports recording a ransom demand, but not a payment, refusal or negotiation outcome.
Whether personal information was accessed, copied or removed remains unresolved. The district said forensic specialists were examining that question, and no reviewed source established a confirmed data breach, leak-site listing or data publication.
Confidence is high that ransomware caused material educational and safety-related disruption because the district directly confirmed the attack type and affected systems. Data availability was affected because core servers, records portals and some information workflows were inaccessible. No stable ransomware-group claim naming the district or its domain was located, so attribution remains unresolved.
The public record does not identify the access vector, ransomware family, dwell time, persistence, affected endpoints or servers, encryption scope, backup impact, ransom amount or payment status. It also does not establish whether sensitive information was acquired, the full recovery cost, the exact date every affected system was restored or whether the district will issue a final recovery notice.

DysruptionHub reported that ransomware disrupted district systems, internet services, phones, staff email, Google accounts, eSchool and Home Access Center. The district closed campus and canceled summer programs because critical operational and safety systems were unavailable.
The district documented continuing recovery, limited system access, unavailable district phones and legacy student-information portals, device-review requirements and no timeline for full restoration. The page states that it was last updated July 17, 2026.
CBS News Chicago reported that the district closed campus after ransomware disrupted internet, phones, emergency notification and public-address systems. The district said it had not yet received a money demand and staff scheduled to work were told to stay home or work remotely.
Superintendent Marcus Campbell said the June incident caused widespread disruption and significant technology damage, leaving core servers inaccessible for about a month. Critical systems were being rebuilt, some tools and processes would not function normally for the start of school, and phased restoration and temporary workarounds would continue.
The Evanston RoundTable reported that the district began a gradual rollout of Infinite Campus, with additional functions expected over the following days and weeks. It also reported that attackers requested a ransom and that officials had not disclosed whether it was paid.
The Evanston RoundTable reported that students returned on August 17. Superintendent Marcus Campbell said opening required an extraordinary collective effort, warned of continuing ripple effects and declined to say whether the district paid.
The current parking page still described a cyber-caused temporary lottery and allocation process and said detailed account information was temporarily unavailable online.
Signed-in members can report an error, update, or missing source.